Most IT leaders who inherit an unfamiliar environment feel the same pressure: prove value quickly, make visible improvements, and show momentum. The natural instinct is to migrate platforms — replace the hypervisor, swap the network stack, modernize the toolchain.
But in operational practice, that instinct is often wrong.
Consider a scenario that plays out regularly across mid-sized organizations and public-sector environments. A new IT manager walks into an estate with fragmented directory services — five separate Active Directory domains, some serving fewer than fifteen users. File servers still running Windows Server 2008. Zero documentation from the outgoing provider. Network hardware approaching end of life. And a list of platform migration ideas that were never executed.
The platform migration proposals — VMware to Proxmox, Fortinet to UniFi — are not unreasonable on their own merits. There may be legitimate cost or licensing arguments behind them. But they address a problem that is not yet acute. The network is functional. The hypervisor is stable. These are not the dependencies most likely to fail in the next six months.
What is likely to fail? Or more precisely, what already represents active operational risk?
Server 2008 left the extended support window years ago. No security patches. No compliance coverage. If one of those file servers is compromised, and there is no forest-level trust structure to contain the breach, the exposure radius could extend well beyond the department that owns the server. In a municipality handling citizen data, public safety systems, or financial records, this is not a theoretical concern. It is a quietly compounding liability.
The five-domain AD architecture compounds this further. Each domain operating independently means separate user provisioning, separate group policy management, separate auditing, and no centralized visibility into authentication activity. For a 150-person organization, this is not just administrative overhead — it is a structural governance gap that makes incident response slower and access control harder to enforce consistently.
Then there is the documentation gap. The outgoing MSP left passwords. They did not leave architecture diagrams, dependency maps, backup verification procedures, or DR runbooks. Without these, even routine maintenance carries elevated risk. A failed backup restore during a minor incident could become a prolonged outage simply because nobody knows the recovery sequence.
So what does a rational first-90-day roadmap look like in this scenario?
First, stabilize the most fragile dependencies before touching anything visible. The Server 2008 file servers are the immediate priority — not because the migration is glamorous, but because the exposure is real and the remediation path is well understood. In parallel, begin documenting the environment as it actually exists, not as it was assumed to exist. Walk the network physically. Verify backup integrity. Test a restore.
Second, address the structural fragmentation. AD consolidation from five domains into a single forest with appropriate OUs is not a weekend project, but starting the design and stakeholder alignment early prevents it from becoming a multi-year drift. Every month the current structure persists adds technical debt and operational friction that compounds.
Third, assess the hardware lifecycle. D-series Fortinet equipment approaching end of life is a predictable problem with a predictable solution. It belongs on the roadmap, but after the security-critical items, not before them.
Only after these foundational risks are managed does a platform migration conversation become operationally responsible. By that point, the organization will also have documentation, a stable directory architecture, and patched servers — which means the migration itself will carry significantly less execution risk.
The lesson that applies well beyond this specific scenario: when you inherit infrastructure, the most visible upgrades are rarely the most urgent. The sequencing of operational risk — not the appeal of a new platform — is what separates a credible IT roadmap from an expensive distraction.